Exam SnowPro Core All QuestionsBrowse all questions from this exam
Question 980

Who can activate a network policy for users in a Snowflake account? (Choose two.)

    Correct Answer: A, E

    In a Snowflake account, the ACCOUNTADMIN role is one of the highest-level admin roles that can activate a network policy. Additionally, any role that has been granted the global ATTACH POLICY privilege can also perform this action. Roles such as USERADMIN or PUBLIC do not have the necessary permissions by default to activate network policies. Thus, the correct selections are ACCOUNTADMIN and any role with the global ATTACH POLICY privilege.

Discussion
Alex_OvidiuOptions: AE

AE Only security administrators (i.e. users with the SECURITYADMIN role) or higher or a role with the global ATTACH POLICY privilege can activate a network policy for an account. Once the policy is associated with your account, Snowflake restricts access to your account based on the allowed list and blocked list.

nexerSnowOptions: AE

AE correct

KarthyJayOptions: AE

AE is correct

Bujji1234Options: AE

Answer - AE Only security administrators (i.e. users with the SECURITYADMIN role) or higher or a role with the global ATTACH POLICY privilege can activate a network policy for an account. Once the policy is associated with your account, Snowflake restricts access to your account based on the allowed list and blocked list.

Jordi204Options: AB

Only security administrators (i.e. users with the SECURITYADMIN role) or higher or a role with the global ATTACH POLICY privilege can activate a network policy for an account. Once the policy is associated with your account, Snowflake restricts access to your account based on the allowed list and blocked list.

CCC1234

note that USERADMIN (B) is lower than SECURITYADMIN